CVE-2024-13717

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 862

Summary

CVE-2024-13717 is a vulnerability affecting the Contact Form and Calls To Action plugin by vcita for WordPress. This issue allows authenticated attackers, with subscriber-level access or higher, to unauthorizedly modify data. The issue stems from a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions, impacting all versions up to and including 2.7.1. As a result, attackers can enable and disable widgets, posing a security risk for WordPress sites using the vcita plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share